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DETAILED ACTION 

Response to Amendment 
This office action is in response to amendment filed on 02/17/06. The amendment filed 
on 02/17/06 have been entered and made of record. 



Response to Arguments 

Applicant's arguments filed 07/05/05 have been fully considered but they are not 
persuasive because of following reasons. 

The applicant argued that Muftic fails to disclose teach or suggest denying access to a 
certification authority's public key, digitally singing said at least one message, by which said 
recipient agrees to rules, and in response to a digital singing, permitting a recipient to utilize said 
public key as recited in claim 1. This is not found persuasive. Muftic discloses verifying the 
identity of the entity to which the certificate is being provided in sections column 10 lines 34-49 
and further in column 6 lines 47-64 and Fig. 1 1 with its corresponding description wherein 
during the process of certification the request for the certificated is verified for authenticity. The 
concept of verifying the authenticity of the request is by definition denying access to the public 
key for the request that is not authentic for use by the processor that creates the request that is not 
authentic. The applicant argued further that the applicant fails to understand how the "general 
public" does not have access to the keys. In the case the certification authority that is higher in 
authority verifies and authorizes the request before providing the certification authority that is 
lower in the hierarchy with the certificate and therefore the public key for use. This indicates 
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that the general public does not have the public key; only those that can create a authentic 
request have the public key for use. 

The applicant argued further that the language "denying access to a certification 
authority's public key and in response to a digital signing by the recipient permits a recipient to 
utilize the public ..." should be given patentable weight. This is found persuasive. However, 
that arguments above about denying access, still apply. 

Accordingly, rejections for claims 1, 18-21, and 72-84 are respectfully maintained. 

Claim Rejections - 35 USC § 102 
The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the 
basis for the rejections under this section made in this Office action: 

A person shall be entitled to a patent unless - 

(e) the invention was described in a patent granted on an application for patent by another filed in the United 
States before the invention thereof by the applicant for patent, or on an international application by another who 
has fulfilled the requirements of paragraphs (1), (2), and (4) of section 371(c) of this title before the invention 
thereof by the applicant for patent. 

The changes made to 35 U.S.C. 102(e) by the American Inventors Protection Act of 1999 
(AEPA) and the Intellectual Property and High Technology Technical Amendments Act of 2002 
do not apply when the reference is a U.S. patent resulting directly or indirectly from an 
international application filed before November 29, 2000. Therefore, the prior art date of the 
reference is determined under 35 U.S.C. 102(e) prior to the amendment by the AIPA (pre-AIPA 
35 U.S.C. 102(e)). 
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Claims 1, 21, 72-73, 77-78, 116-120, and 129-130 are rejected under 35 U.S.C. 102(e) as 
being anticipated by Muftic (US 5,745,574). 

Claims 1 and 73: Muftic' s patent discloses certifying authority issues digital certificate 
identifying users of the system in (Fig. 26). Muftic discloses digital certificates being digitally 
signed with a private key of certifying authority to form a digital signature and requiring a public 
key of certifying authority in order to verify digital signature in (column 14, lines 54-63). Muftic 
discloses a user transaction in a cryptographic system requires verification by a recipient of user 
transaction verification based on information in digital certificates and requiring the public key 
in (column 10 lines 34-49). Muftic discloses denying access to public key in (column 4 lines 65- 
67; column 5 lines 1-2; column 10 lines 34-49 and further in column 6 lines 47-64 and Fig. 1 1 
with its corresponding description). Muftic discloses providing recipient with at least one 
message containing the rules of the system including a rule regarding maintaining secrecy of 
public key in (column 10 lines 52-57). Muftic discloses digitally signing by recipient at least one 
message which recipient agrees to rules and permitting recipient to utilize public key in (column 
1 1 lines 29-53; column 12 lines 32-40). 

Claims 21 and 72: Muftic discloses user transaction is invalid until digital signing is 
performed in (column 12 lines 22-43). 

Claim 77: Muftic discloses user transaction of said recipient in the system is invalid until 
said digital signing is performed (column 12 lines 30-35). 

Claim 78: Muftic discloses responding to said signing by said recipient, a certifying 
authority accepting a transaction from said recipient, said transaction based on a user transaction 
of said recipient in the system (column 10 lines 45-57). 
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Claim 1 16: wherein the public key becomes inactive after a certain time period, the 
system further comprising: after the public key becomes inactive, in response to a demonstration 
by the recipient of agreement or consistency with one or more of the rules, activating the inactive 
public key (Fig 13 and corresponding description). 

Claim 1 17: wherein said demonstration includes information identifying operational 
capabilities of a secure device and further including information uniquely binding said recipient 
to said demonstration by the recipient of agreement or consistency with one or more of the rules 
(column 10 lines 45-57). 

Claim 118 wherein the public key is certified by an authority (column 5 lines 20-40). 

Claims 119 and 130: wherein said permitting comprises making the public key available 
by providing access to an inaccessible public key (Fig. 10). 

Claim 120 and 129: further comprising: a certifying authority accepting a transaction 
from the recipient, the transaction based on a transaction of the recipient in the cryptographic 
system, after demonstration by the recipient of agreement or consistency with one or more of the 
rules (column 6 lines 1-5 and column 10 lines 50-57). 
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Claim Rejections - 35 USC § 103 
The following is a quotation of 35 U.S.C. 103(a) which forms the basis for all 
obviousness rejections set forth in this Office action: 

(a) A patent may not be obtained though the invention is not identically disclosed or described as set forth in 
section 102 of this title, if the differences between the subject matter sought to be patented and the prior art are 
such that the subject matter as a whole would have been obvious at the time the invention was made to a person 
having ordinary skill in the art to which said subject matter pertains. Patentability shall not be negatived by the 
manner in which the invention was made. 

Claims 18, 20, 74, 79-80, 83-84, 92-93, 109-115, 121-125, 127-128, and 131 are rejected 
under 35 U.S.C. 103(a) as being unpatentable over Muftic (5,745,574) in view of Curry 
(5,940,510). 

Claims 18 and 74: Muftic does not specifically disclose providing recipient with a secure 
device containing public key, wherein public key cannot be obtained from secure device. 
Curry's patent discloses secure device containing public key, wherein public key cannot be 
obtained from secure device (column 4 lines 49-55). It would have been obvious to a person of 
ordinary skill in the art at the time the invention was made to employ a secure device containing 
public key wherein public key cannot be obtained from secure device as taught in Curry with 
public key storage of Muftic in so that the key can be protected and secured at all times against 
tampering/malicious attacks thus providing secure means to conduct transactions by the users. 

Claim 20: Muftic discloses containing rules of system including a rule regarding 
maintaining secrecy of public key. Muftic does not include a rule to pay for use by said recipient 
of intellectual property provided through the system. Curry teaches the monetary value of the 
recipient is decreased (paying) for use of the system when information is matched (rule, column 
7 lines 21-35). It would have been obvious to a person of ordinary skill in the art at the time the 
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invention was made to include a rule to pay as taught in Curry to the system in Muftic in order to 
provide recipient's privileges and conveniences for the use of the system. 

Claim 79: Muftic's patent discloses certifying authority issues digital certificate 
identifying users of the system in (Fig. 26). Muftic discloses providing a recipient with a 
message containing rules of said system (column 10 lines 52-57). This system disclosed by 
Muftic includes an inactive form of said public key (column 15 lines 32-36 in combination with 
column 12 lines 60-64). In response to said recipient digitally signing said message, activating 
said public key in said secure device (column 15 lines 36-43). 

Muftic does not specifically disclose providing recipient with a secure device containing 
public key, wherein public key cannot be obtained from secure device. Curry's patent discloses 
secure device containing public key, wherein public key cannot be obtained from secure device 
(column 4 lines 49-55). It would have been obvious to a person of ordinary skill in the art at the 
time the invention was made to employ a secure device containing public key wherein public key 
cannot be obtained from secure device as taught in Curry with public key storage of Muftic in so 
that the key can be protected and secured at all times against tampering/malicious attacks thus 
providing secure means to conduct transactions by the users. 

Claim 80: Muftic discloses a public key that is a public key of a certifying authority, said 
providing is performed by a certifying authority (column 10 lines 35-57), said digitally signing 
comprises hashing said message to obtain a hashed document, digitally signing said hashed 
document to form a digital agreement (column 12 lines 54-56), and returning said digital 
agreement to said certifying authority, and said activating is performed by said certifying 
authority (column 12 lines 7-21). 
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Claims 83 and 92: Muftic discloses user transaction of said recipient in the system is 
invalid until said digital signing is performed (column 12 lines 30-35). 

Claims 84 and 93: Muftic discloses responding to said signing by said recipient, a 
certifying authority accepting a transaction from said recipient, said transaction based on a user 
transaction of said recipient in the system (column 10 lines 45-57 in combination with column 1 1 
lines 60-65). 

Claim 109: where, in the cryptographic system, a certifying authority issues digital 
certificates identifying participants of the cryptographic system (Fig. 3), the digital certificates 
being digitally signed with a private key of the certifying authority to form a digital signature 
(part 320 Fig. 3) and requiring a public key of the certifying authority in order to verify the 
digital signature (column 6 line 65 to column 7 line 20), and a participant transaction requires 
verification by a recipient of the participant transaction, the verification based on information in 
a digital certificate and requiring the public key (column 5 lines 5-12). 

Claim 110: wherein the public key in the secure device becomes inactive after a certain 
time period, the method further comprising: 

after the public key becomes inactive, in response to a demonstration by the recipient of 
agreement or consistency with one or more of the rules, activating the inactive public key in the 
secure device (Fig. 13 and column 10 lines 50-57). 

Claim 111: wherein said demonstration includes information from the secure device 
identifying operational capabilities of the secure device and further including information 
uniquely binding said recipient to said demonstration by the recipient of agreement or 
consistency with one or more of the rules (10 lines 45-50). 
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Claim 112: wherein the public key is certified by an authority (column 5 lines 20-40). 

Claim 113: further comprising: a certifying authority accepting a transaction from the 
recipient, the transaction based on a transaction of the recipient in the cryptographic system, after 
demonstration by the recipient of agreement or consistency with one or more of the rules 
(column 6 lines 1-5 and column 10 lines 50-57). 

Claim 114 wherein the rules comprise a rule regarding maintaining secrecy of the public 
key (column 10 lines 50-57). 

Claim 115: wherein said activating comprises activating said public key in said secure 
device in response to a predetermined transaction with said secure device, said predetermined 
transaction including information from the secure device identifying operational capabilities of 
the secure device and uniquely identifying said secure device and further including information 
uniquely binding said recipient to said predetermined transaction (). 

Claim 121 wherein said permitting comprises: in response to a predetermined transaction 
with a device, activating said public key in said secure device, said predetermined transaction 
including information from the secure device identifying operational capabilities of the secure 
device and uniquely identifying said secure device and further including information uniquely 
binding said recipient to said predetermined transaction, wherein said public key cannot be 
obtained from said device (Fig 13). 

Muftic does not specifically disclose providing recipient with a secure device containing 
public key, wherein public key cannot be obtained from secure device. Curry's patent discloses 
secure device containing public key, wherein public key cannot be obtained from secure device 
(column 4 lines 49-55). It would have been obvious to a person of ordinary skill in the art at the 
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time the invention was made to employ a secure device containing public key wherein public key 
cannot be obtained from secure device as taught in Curry with public key storage of Muftic in so 
that the key can be protected and secured at all times against tampering/malicious attacks thus 
providing secure means to conduct transactions by the users. 

Claim 122: wherein a device contains an inactive form of said public key and said 
permitting comprises activating said inactive public key in said (Fig. 13). 

Muftic does not specifically disclose providing recipient with a secure device containing 
public key, wherein public key cannot be obtained from secure device. Curry's patent discloses 
secure device containing public key, wherein public key cannot be obtained from secure device 
(column 4 lines 49-55). It would have been obvious to a person of ordinary skill in the art at the 
time the invention was made to employ a secure device containing public key wherein public key 
cannot be obtained from secure device as taught in Curry with public key storage of Muftic in so 
that the key can be protected and secured at all times against tampering/malicious attacks thus 
providing secure means to conduct transactions by the users. 

Claim 123: wherein said permitting comprises transferring said public key to said device. 

Muftic does not specifically disclose providing recipient with a secure device containing 
public key, wherein public key cannot be obtained from secure device. Curry's patent discloses 
secure device containing public key, wherein public key cannot be obtained from secure device 
(column 4 lines 49-55). It would have been obvious to a person of ordinary skill in the art at the 
time the invention was made to employ a secure device containing public key wherein public key 
cannot be obtained from secure device as taught in Curry with public key storage of Muftic in so 
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that the key can be protected and secured at all times against tampering/malicious attacks thus 
providing secure means to conduct transactions by the users. 

Claim 124: wherein said public key is provided in a secure device. 

Muftic does not specifically disclose providing recipient with a secure device containing 
public key, wherein public key cannot be obtained from secure device. Curry's patent discloses 
secure device containing public key, wherein public key cannot be obtained from secure device 
(column 4 lines 49-55). It would have been obvious to a person of ordinary skill in the art at the 
time the invention was made to employ a secure device containing public key wherein public key 
cannot be obtained from secure device as taught in Curry with public key storage of Muftic in so 
that the key can be protected and secured at all times against tampering/malicious attacks thus 
providing secure means to conduct transactions by the users. 

Claim 125 method further comprising: after said public key becomes inactive, in 
response to a demonstration by the recipient of agreement or consistency with one or more of the 
rules, activating said inactive public key in said secure device (Fig. 13). 

Claim 127: said permitting comprises transferring the public key to a secure device, 
wherein the public key cannot be obtained from the secure device. 

Muftic does not specifically disclose providing recipient with a secure device containing 
public key, wherein public key cannot be obtained from secure device. Curry's patent discloses 
secure device containing public key, wherein public key cannot be obtained from secure device 
(column 4 lines 49-55). It would have been obvious to a person of ordinary skill in the art at the 
time the invention was made to employ a secure device containing public key wherein public key 
cannot be obtained from secure device as taught in Curry with public key storage of Muftic in so 
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that the key can be protected and secured at all times against tampering/malicious attacks thus 
providing secure means to conduct transactions by the users. 

Claim 128: where, in the cryptographic system, a certifying authority issues digital 
certificates identifying participants of the cryptographic system, the digital certificates being 
digitally signed with a private key of the certifying authority to form a digital signature and 
requiring a public key of the certifying authority in order to verify the digital signature, and a 
participant transaction requires verification by a recipient of the participant transaction, the 
verification based on information in a digital certificate and requiring the public key (Fig. 7 and 
column 6 lines 1-10). 

Muftic does not specifically disclose providing recipient with a secure device containing 
public key, wherein public key cannot be obtained from secure device. Curry's patent discloses 
secure device containing public key, wherein public key cannot be obtained from secure device 
(column 4 lines 49-55). It would have been obvious to a person of ordinary skill in the art at the 
time the invention was made to employ a secure device containing public key wherein public key 
cannot be obtained from secure device as taught in Curry with public key storage of Muftic in so 
that the key can be protected and secured at all times against tampering/malicious attacks thus 
providing secure means to conduct transactions by the users. 

Claim 131 wherein said permitting comprises: in response to a predetermined transaction 
with a device, activating said public key in said secure device, said predetermined transaction 
including information from the device identifying operational capabilities of the secure device 
and uniquely identifying said device and further including information uniquely binding said 
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recipient to said predetermined transaction, wherein said public key cannot be obtained from said 
secure device. 

Claim 126 is rejected under 35 U.S.C. 103(a) as being unpatentable over Muftic and 
Curry as applied to claim 125 above, and further in view of Ryder (4,953,209). 

Claim 126: wherein further including information uniquely binding said recipient to said 
demonstration by the recipient agreement or consistency with one or more of the rules. 

Muftic does not specifically disclose providing recipient with a secure device containing 
public key, wherein public key cannot be obtained from secure device. Curry's patent discloses 
secure device containing public key, wherein public key cannot be obtained from secure device 
(column 4 lines 49-55). It would have been obvious to a person of ordinary skill in the art at the 
time the invention was made to employ a secure device containing public key wherein public key 
cannot be obtained from secure device as taught in Curry with public key storage of Muftic in so 
that the key can be protected and secured at all times against tampering/malicious attacks thus 
providing secure means to conduct transactions by the users. 

Although Muftic discloses policies or rules and authorization privileges Muftic does not 
expressly disclose the demonstration including information identifying operational capabilities of 
the device. 

Ryder teaches demonstration includes information identifying operational capabilities of 
the device (column 5 and column 3 linees 56-62). 

At the time the invention was made, it would have been obvious to a person of ordinary 
skill in the art to confirm that use has received the object agreed upon and agree on the terms and 
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conditions as in Ryder in the system of Muftic. One of ordinary skill in the art would have been 
motivated to do this because it would remove the need for documents that are normally require 
registered and signed receipt mail delivery. 

Allowable Subject Matter 
Claims 19, 75-76, and 81-82 are objected to as being dependent upon a rejected base 
claim, but would be allowable if rewritten in independent form including all of the limitations of 
the base claim and any intervening claims. 

Conclusion 

THIS ACTION IS MADE FINAL. Applicant is reminded of the extension of time 
policy as set forth in 37 CFR 1.136(a). 

A shortened statutory period for reply to this final action is set to expire THREE 
MONTHS from the mailing date of this action. In the event a first reply is filed within TWO 
MONTHS of the mailing date of this final action and the advisory action is not mailed until after 
the end of the THREE-MONTH shortened statutory period, then the shortened statutory period 
will expire on the date the advisory action is mailed, and any extension fee pursuant to 37 
CFR 1 . 1 36(a) will be calculated from the mailing date of the advisory action. In no event, 
however, will the statutory period for reply expire later than SIX MONTHS from the mailing 
date of this final action. 
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Any inquiry concerning this communication or earlier communications from the 
examiner should be directed to Paula W. Klimach whose telephone number is (571) 272-3854. 
The examiner can normally be reached on Mon to Thr 9:30 a.m to 5:30 p.m. 

If attempts to reach the examiner by telephone are unsuccessful, the examiner's 
supervisor, Kim Vu can be reached on (571) 272-3859. The fax phone number for the 
organization where this application or proceeding is assigned is 571-273-8300. 

Information regarding the status of an application may be obtained from the Patent 
Application Information Retrieval (PAIR) system. Status information for published applications 
may be obtained from either Private PAIR or Public PAIR. Status information for unpublished 
applications is available through Private PAIR only. For more information about the PAIR 
system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR 
system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). 
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